Most Popular Detection 2026: Suspicious npm/PyPI Post-Install Script Spawning Shell or Credential Harvesting

This rule detects potentially malicious behavior in package manager post-install scripts (npm, pip). It monitors for child processes like shells, network utilities (curl, wget), or command-line arguments indicative of credential harvesting (e.g., accessing .ssh, .aws/credentials, environment variables) initiated by package management processes.